Question

Difficulty: MediumSocial Engineering Attacks and Vectors

An enterprise system administrator receives an unsolicited telephone call from an individual claiming to represent the organization's central data center team. The caller states that an emergency database synchronization failure is occurring and demands that the administrator immediately provide their two-factor authentication bypass code to prevent widespread data loss. Which social engineering attack vector is the caller primarily utilizing?

  1. VishingAnswer
  2. B
    Smishing
  3. C
    Baiting
  4. D
    Watering hole attack

Answer

The correct answer is vishing, as the attack relies on voice communication over the telephone combined with an urgent pretext.
The attack relies on an interactive voice phone call to manipulate the victim into exposing sensitive multi-factor authentication credentials under the guise of an urgent technical issue. This directly defines vishing (voice phishing).

Step-by-Step Solution

1
Identify the communication medium used by the attacker in the scenario.
The attack occurs via an unsolicited telephone call.
The medium (voice call vs SMS vs email vs web) distinguishes primary social engineering attack vector categories.
2
Analyze the adversary's tactic and psychological trigger.
The attacker creates a fake technical emergency (pretexting) to create urgency over a phone call.
Voice-based social engineering combined with scenario-based pretexting defines voice phishing (vishing).
3
Select the social engineering term matching voice-based communication.
Vishing is the correct classification.
Vishing specifically denotes phishing attacks conducted over voice telephone systems.

Key Concept

Vishing and Voice-Based Pretexting Attacks
Rate this question